Privacy
Effective 13 September 2026. This page describes what Docent does today. When the product changes, this page changes with it.Two kinds of people
Docent is installed by a company into its own app. That company is our customer and signs in to the Console. The people using the customer’s app are end users. End users never create a Docent account and never give us a password. What follows is mostly about them, because they are the people the guide sees.
What the guide sees
The guide reads the accessibility tree of the page the end user is on: the roles, names and states of controls, their positions, the current route and scroll position. It does not take screenshots. It sends changes to that tree to our servers so the guide can answer about the page in front of the user.
What is masked before anything leaves the browser
Before a snapshot is sent, every input value is removed, every region the customer marked with data-guide-mask is removed, and text matching an email address, a card number or a phone number is replaced. This happens in the browser. If the masking step fails for any reason, nothing is sent at all. The customer can mark regions as readable if the guide needs them; nothing is readable by default.
The microphone
The guide never opens a microphone until the end user agrees to it in a prompt that says what will happen. After each turn the microphone closes. A visible indicator is shown while it is open. Declining leaves the guide fully usable by typing.
What is stored, and for how long
Docent stores the masked text of each turn, which tools the guide used, how long the turn took, the routes a session visited, and a small set of named events such as whether the guide was opened, muted or dismissed. Each customer sets a retention period for each of their environments between 0 and 90 days. Automatic deletion at that boundary is not yet running; until it is, deletion happens on request.
Docent does not store raw audio. Voice is processed by the vendor named on the sub-processors page under that vendor’s API terms; where the vendor offers a retention control, it is switched off. Docent’s store is the system of record.
What is never done
No customer data is used to train models. No end-user data is shared between customers. End users are identified only by the id their app passes to the guide, and a customer may additionally sign that id so the session is marked verified.
This website
usedocent.com sets no cookies and loads no analytics or third-party scripts, which is why there is no cookie banner. The Console at app.usedocent.com sets the cookies it needs to keep you signed in and nothing else.
Contact
Questions about this page go to privacy@usedocent.com. Deletion and export requests for a customer’s data are handled through the Console or by the same address.
